hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

setthesun
Jepg of Death;
http://www.k-otik.com/exploits/09252004.JpegOfDeath.c.php

sh;
http://www.k-otik.com/exploits/09222004.ms04-28.sh.php

C;
http://www.k-otik.com/exploits/09222004.ms04-28-cmd.c.php

I tried C version (with custom shellcode and default) and it's always crash whole IExplorer.exe (XP non-patched)


Is there any stable version ? Execute without crashing...
Zero-X
I tryed JPEG of death but doesnt seems to work perfectly when you send it to a remote box..
boshcash
not enough tests didnt see any jpg exploit working didnt try sh files im on a windows system , also looking for an exploit which u can attach a real jpg to the file so it doesnt say drawing failed
setthesun
I think the best way to exploit this we should try to exploit Outlook Express and Office Applications, IE is not vulnerable directly. Also I should to force IE to show only image but it's not working too.

Also I try to send email linked HTML it's not working again.
Embedding may works but is there any idea how can I embed image to Outlook ?

If I can try to embed image viA standard HTML email sender (like outlook etc.) it's not working. We should write / embed directly with an application.

Any idea ?



This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.